Secure RD Gateway with PhoneFactor using Radius


i have followed document "secure rd gateway phonefactor using radius" found on phonefactor customer portal unable work.

i first set without pf , works after making modifications according document unable reach remote desktop.

i have windows server 2008r2 server alone in our dmz acting gateway remote desktops in our production lan.

is able work using local sam or require ad membership or ldap bind? not specify in document.

the pf authentication works when directly rdp server.

 i asking here because saw microsoft had acquired phonefactor , haven't found better forum approach.

thank you.


i have gotten working.

a couple of items need added phonefactor document application; there must @ least 2 servers, rd gateway , phonefactor agent on separate machines. not work if put pf , rd gateway on same machine, if change ports on nps and/or pf.

also if using on servers joined domain rd gateway server must member of domain group "ras , ias servers"

i wanted on stand alone servers in dmz because of way authentication gets passed server pf on not authenticate username being passed rdg identical account set on both servers.

when tried set stand alone got error following:

with radius rejection first encountered:

2013-01-17t17:10:43.656250z|0|2804|2824|prfad|event 3.

2013-01-17t17:10:43.656250z|0|2804|2824|prfad|sock 0x00000000000000e4 2013-01-17t17:10:43.671875z|0|2804|2824|pfrad|code 2 - access_accept.

2013-01-17t17:10:43.671875z|0|2804|2992|pfrad|calling pfauthuser('remote01\testuser', '', 1) 2013-01-17t17:10:43.671875z|0|2804|2992|pfrad|authresult = 0 2013-01-17t17:10:43.671875z|0|2804|2992|pfrad|rawcallstatus = 4294967195 2013-01-17t17:10:43.671875z|0|2804|2992|pfrad|rawmessagestatus = 0 2013-01-17t17:10:43.671875z|e|2804|2992|pfrad|phonefactor auth failed.

2013-01-17t17:10:43.671875z|e|2804|2992|pfrad|sending access_reject username remote01\testuser

now in pf has option set how users authenticated, there 3 choices: case-sensitive string match, ldap , windows sid.

if had selected case-sensitive string , set users in format of servername\username might have worked didn't test that.

my manager wanted keep having place manage usernames , passwords. there not method of changing passwords on rd gateway allow users manage own.

i had issue think occurred because of fact installed pf while server alone , after joined them domain pf not work. when pf installs creates required windows firewall rules. created them public profile , after adding domain there no rule pf in domain profile , had modify rules include domain.

hope helps else.



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL